Description
This vulnerability allows a malicious actor with access to add or modify content in an instance of the Backstage software catalog to inject script URLs in the entities stored in the catalog. If users of the catalog then click on said URLs, that can lead to an XSS attack.
Recommendation
Update the @backstage/catalog-model package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.2.0
- Patched version(s): 1.2.0
References
Could your website be exposed too?
SmartScanner can check your website for Cross site scripting Vulnerability in backstage Software Catalog and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Cross site scripting Vulnerability in backstage Software Catalog - @backstage/core-components - CVE-2023-25571
- angular-ui-notification Cross-site Scripting vulnerability - CVE-2023-34840
- @excalidraw/excalidraw Cross-site Scripting vulnerability - CVE-2023-26140
- Layui cross-site scripting (XSS) vulnerability - CVE-2023-50550


